MCP server for SecObserve: triage findings, manage products, import scan reports and SBOMs.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
MCP server for SecObserve β Triage, import and administration from an agent
Tools β’ Install β’ Configure β’ Register with a client β’ Design
secobserve-mcp exposes the SecObserve REST API to an LLM agent over the Model Context Protocol: browse and triage observations, manage products, branches and rules, import scan reports and SBOMs, run scans and background jobs, generate VEX documents. Transport is stdio by default. Listed in the official MCP Registry as io.github.nh4ttruong/secobserve-mcp.
18 tools, not one per endpoint. SecObserve has ~50 REST resources and ~40 named actions; registering a tool for each would cost more context than the data ever returns, so the API is modelled as data and the tools are the interface to it.
| Tool | Purpose |
|---|---|
secobserve_list_resources | The catalogue: every resource, its verbs, its actions. Makes no API call, so it is free to call first. |
secobserve_describe_resource | Exact filters, fields and enums, read from the running instance's OpenAPI schema. |
secobserve_list / _get | Read, with filters, sorting, pagination and projection. |
secobserve_create / _update / _delete | CRUD over any resource in the catalogue. |
secobserve_call_action | The long tail: apply_rules, copy, simulate, license_overview, exports. |
secobserve_assess_observation | Triage one finding. Writes an observation log, honours the approval workflow. |
secobserve_bulk_assess_observations | The same assessment across up to 250 findings. |
secobserve_approve_observation_log | Approve or reject pending assessments (four-eyes). |
secobserve_product_metrics | Pre-aggregated counts: current, timeline, the delta between two dates, and how stale they are. |
secobserve_upload_file | Import a scan report, SBOM or VEX document from disk. |
secobserve_api_import | Pull findings through a stored API configuration. Blocks; a timeout reports the work as still running and where to watch it land. |
secobserve_trigger_scan | Run SecObserve's built-in OSV or VulnerableCode scan. Same blocking behaviour. |
secobserve_run_periodic_task | Trigger a background job, or list the registered ones. |
secobserve_status | Version, health, public settings, queue statistics, PURL types. |
secobserve_vex_document | Generate or revise a CSAF / OpenVEX / CycloneDX document. |
Six prompts, for the work that is a sequence of calls rather than one. A prompt is fetched by name when someone picks it, so it costs nothing per session β unlike a tool schema, which is sent on every connection.
| Prompt | Purpose |
|---|---|
triage-product | Work one product's open findings, highest severity and fix_available first, assessing each with evidence. |
daily-changes | What changed since local midnight: new, parser-changed, resolved, human-assessed. |
weekly-changes | The same feed over the past 7 days, broken down by day. |
daily-report | Today's counts per product, what moved today, what is still open. |
weekly-report | The same three parts over the past 7 days, for the report someone sends on. |
monthly-report | A month's closing numbers and the month-over-month delta. |
Each one carries the caveats that decide whether the report is right: metrics cover the default branch only and answer 200 with every count at zero when the job has not run, no filter expresses a calendar month, and nothing in SecObserve is a due date or an SLA.
uvx downloads and runs it without installing anything permanently. In VS Code: one-click install.
To put it on your PATH instead:
Once you have done that, uv tool owns the name: a bare uvx secobserve-mcp runs that pinned copy forever and never notices a newer release, so keep it current with uv tool upgrade secobserve-mcp.
The client configurations below therefore say uvx secobserve-mcp@latest, which revalidates against PyPI on each launch β once per client session, not once per command.
--check deliberately stays on the bare name, because its job is to report on the copy your clients are actually running.
From a checkout, for development:
| Variable | Default | Notes |
|---|---|---|
SECOBSERVE_BASE_URL | http://localhost:8000 | Base URL without /api. |
SECOBSERVE_API_TOKEN | β | User or product API token. Recommended. |
SECOBSERVE_JWT | β | Alternative to an API token. |
SECOBSERVE_TIMEOUT | 60 | Seconds. SecObserve imports and scans inside the request, and a timeout does not cancel one; raise it to get the counts back from the call itself. |
SECOBSERVE_VERIFY_SSL | true | Set false only for a self-signed dev certificate. |
SECOBSERVE_READ_ONLY | false | true refuses every non-GET call. |
SECOBSERVE_ALLOW_DELETE | false | secobserve_delete is off until this is set. |
SECOBSERVE_IMPORT_DIR | working directory | Uploads may only be read from this tree. |
SECOBSERVE_EXPORT_DIR | ./secobserve-exports | Exports and VEX documents are written here. |
SECOBSERVE_AUDIT_LOG | true | One JSON line per tool call on stderr. false switches it off. |
Create a user API token:
Check the wiring before handing it to a client:
It prints the instance version, the authenticated user, whether read-only and delete are enabled, and how this install compares to the newest release on PyPI. That last part is the only place this server calls pypi.org, it needs one short-lived request, and it degrades to a single line when the index is unreachable.
The image is built for linux/amd64 and linux/arm64, runs as a non-root user, and answers GET /healthz with its version.
/healthz is liveness only and never calls SecObserve, so a backend outage does not get this server restarted.
--shared-identity is required and not in the image's default command: the token is baked into the environment, so every caller of the port acts as that one SecObserve identity, and the server refuses to start over HTTP until someone says that is intended.
It then refuses every write, because an assessment made under a shared token records the wrong actor in the observation log and in four-eyes approval.
Arguments to docker run replace CMD rather than extend it, which is why the transport flags are repeated above.
Keep it behind a gateway that authenticates the caller, and off any public port.
For a single user, uvx over stdio is the better fit: one process, one token, writes included.
The server prints its own registration snippet, so none of the blocks below have to be copied by hand:
It reads SECOBSERVE_BASE_URL from the environment and always leaves the token
as a placeholder β the snippet is meant to be pasted somewhere, and a token
should not travel with it. The hint goes to stderr, so --print-config json > mcp.json writes a clean file.
In ~/.codex/config.toml:
Most clients take the same JSON shape:
For a shared deployment, run streamable HTTP with stateless JSON behind a gateway that authenticates the caller:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/secobserve-mcp)<a href="https://allmcps.com/mcp/secobserve-mcp"><img src="https://allmcps.com/api/badge/secobserve-mcp?style=directory" alt="Secobserve MCP on AllMCPs" /></a>